Live data from Hacker News

Cybersecurity Incident Involving Consumer Information

investor.equifax.com

291–300 of 551 posts

Re: Cybersecurity Incident Involving Consumer Information

#291

"Three Equifax Inc. senior executives sold shares worth almost $1.8 million in the days after the company discovered a security breach that may have compromised information on about 143 million U.S. consumers." https://www.bloomberg.com/news/articles/2017-09-07/three-equ... Edit: Also discussed here https://news.ycombinator.com/item?id=15196309

So, that should definitely get them busted for insider trading, no?

It depends...

Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 scheduled trading plans.

The three “sold a small percentage of their Equifax shares,” Ines Gutzmer, a spokeswoman for the Atlanta-based company, said in an emailed statement. They “had no knowledge that an intrusion had occurred at the time.”

The timing is extremely suspicious. But - if they can prove they didn't know, they're in the clear. Of course a breech like this quickly goes to the board, and it's hard to imagine that the CFO and President of US Information Solutions wouldn't know.

Re: Cybersecurity Incident Involving Consumer Information

#292
post #132
post #29

Earlier quoted context omitted.

I mean the companies like Equifax. Is there nothing illegal about being careless enough to leak this much important information to hackers? I personally think they should be held accountable.

Putting aside the whole "punishing the victim" argument, the problem is that it's excruciatingly hard to draw a line between "being careless" and "you did everything right but it still wasn't enough", and thus it's really hard to punish someone for cybersecurity mistakes. I work in cybersec consulting, and it's certainly true that a large number of companies are simply not investing enough money/time/effort into cybe…

>and thus it's really hard to punish someone for cybersecurity mistakes

No. If you take it upon yourself to hold this information, you are accepting the responsibility for its disclosure. If you are not willing to accept penalty for this happening despite your best efforts, you should not be doing it.

Re: Cybersecurity Incident Involving Consumer Information

#293

Earlier quoted context omitted.

So, that should definitely get them busted for insider trading, no?

It depends... Regulatory filings show that three days later, Chief Financial Officer John Gamble sold shares worth $946,374 and Joseph Loughran, president of U.S. information solutions, exercised options to dispose of stock worth $584,099. Rodolfo Ploder, president of workforce solutions, sold $250,458 of stock on Aug. 2. None of the filings lists the transactions as being part of 10b5-1 scheduled trading plans. The…

> The timing is extremely suspicious. But - if they can prove they didn't know, they're in the clear.

Burden of proof for criminal cases is the other way around. They will likely spend lots on legal fees just trying to prove they didn't know about the hack at the time they decided to sell. They will likely end up settling out of court (guilty or not) because that's how the US legal system works.

Also important -- July 29 is when Equifax claims they noticed the issue.

Re: Cybersecurity Incident Involving Consumer Information

#294
post #93

Suppose Alice is a "victim of identity theft". BigBank gives $10k to Fraudster as a loan, thinking that Alice is the actual recipient. Experian, Transunion and Equifax report this loan as a debt which Alice owes to BigBank. Who is the real victim? The credit reporting agencies want to convince people that the consumer is the victim, and so Alice bears the burden and risk of clearing her name. But it is the credit rep…

> It is Experian, Transunion and Equifax, by holding this fraudulent loan against Alice, who are victimizing Alice.

Credit Reporting agencies report the data passed to them by companies such as banks. In your scenario BigBank thinks it's given a loan to Alice, and when they don't get repaid, report that to the CRAs. Alice is a victim of the thief because her identity was appropriated to secure the funds. BigBank is a victim of the thief because they were defrauded. The CRA is a victim because they were just reporting the information that was provided to them in good faith by their customer BigBank. So saying that the CRAs are "victimizing" Alice is completely false.

Alice bears the burden and risk of clearing her name, just as a victim of car theft bears the burdens of reporting the crime, getting another vehicle, dealing with the any outstanding loans, etc. These burdens are inflicted by the thief, not the bank or CRA.

> perpetuated by the credit reporting agencies as a way to absolve themselves of responsibility, [...] and to avoid realistic identity-verifiction which might slow or complicate the practice of issuing large amounts of debt to the general public.

This completely misunderstands the role of a CRA. The CRA doesn't have to verify identity, it's up to the credit grantor to ensure they are dealing with the person they think they are.

Re: Cybersecurity Incident Involving Consumer Information

#295
post #216

Earlier quoted context omitted.

It is a protection racket that shifts the risks and costs from the financial system to consumers.

Same with chip and pin here in the UK

At least you get the pin as well. We just have chip, and it does ~nothing.

Re: Cybersecurity Incident Involving Consumer Information

#296
post #2

> approximately 143 million U.S. consumers. This was only a matter of time. We can rotate credit card numbers, but sadly not a SSN. I wish I could rotate my US social security number when significant exposure happens (this would be the 4th or 5th time in 24 months my data has been exposed). Assuming legislation passed that allowed you to cancel an exposed SSN and get a new one, what would it take for that to happen?…

I think the true error in process is that a SSN is considered to be a secret, unique ID, and many (many!) institutions allow you to use it as a proof of identity. It's short, guessable, would fail all of their own password requirements, and yet somehow it gets a free pass. I just consider my SSN to be public, and move about my digital life with that assumption. I don't go plastering it on walls, but if I encounter a…

My hope is that with this breach, someone will finally be able to hit Congress over the head with a smart stick and make them realize this.

Re: Cybersecurity Incident Involving Consumer Information

#297
post #269

Earlier quoted context omitted.

And that unique long pin definitely isn't stored in plaintext in the next column over in their database, right?

"don't worry, your 12 digit pin is securely encrypted with md5" /s

md5? They use triple ROT13.

Re: Cybersecurity Incident Involving Consumer Information

#298
post #91

Earlier quoted context omitted.

> This is not proof of identity. What is it then? I've seen it used as a quasi-password by car hire companies to access driving license history.

>What is it then? It is the username you are issued by the government. It is solely used to identify you.

> It is solely used to identify you.

Not exactly. It's used to map your Social Security account to other records they have about you. It's not, by itself, identification.

Re: Cybersecurity Incident Involving Consumer Information

#299
post #211

Earlier quoted context omitted.

This is actually a major inconvenience. You won't be able to apply for credit cards or get a loan to buy a car if you have a credit freeze. You have to unfreeze and re-freeze each time you apply for a credit card, and this costs about $30.

How often to you apply for credit? It is, in any case, far less of an inconvenience than not paying the protection racket, having someone impersonate you, and having the credit oligopoly lie about you because of it, leaving you to somehow clean up their mess.

Some folks churn, so they apply for credit several times a month. It's not a very small niche community either.

Re: Cybersecurity Incident Involving Consumer Information

#300
post #206

Earlier quoted context omitted.

$1k, $100, that's far too low in my opinion even for a warning shot. As someone who has had their info leaked by two universities before, both of whom subsequently paid for multiple years of credit/fraud protection, the sheer pain and stress of having random credit cards frozen and need to be replaced is worth far more than that dollar amount of my time. This is potentially messing with people's livelihoods with long…

$100 per each individual would be 14 billion dollars... Which would definitely put Equifax out of business.

Perfect. If they're in the business of selling access to sensitive information and cannot keep said sensitive information safe, they should not be allowed to continue to leak that sensitive information.
Post reply on HN